1. Introduction and Scope
This Privacy Policy explains how ARBR Inc. d/b/a Arbiter Defense Group (“Arbiter”) collects, uses, and shares information in connection with the Client App and the protective-security engagements (each an “Engagement”) it supports. This Policy applies to Clients — the individuals a Provider Firm protects through an Engagement — and, where applicable, to an Entity of Interest (“EoI”), a person identified in connection with an Engagement’s threat assessment who is not themselves a Client App user. Capitalized terms not defined in this Policy have the meaning given in the Client App Terms of Service.
This Policy operates together with, and does not narrow, the Client App Terms of Service and the Data Minimization and Retention Policy.
2. Information You Provide
When you or your Provider Firm set up your Client App account or participate in an Engagement, we collect information you or your Provider Firm provide directly, including:
Identity and contact information — name, email, phone number, and similar account details.
Engagement information — the scope of your protective-security engagement, your itinerary, sites and locations relevant to the engagement, and information about individuals or circumstances that inform your threat assessment.
Communications — messages you send through the Client App to your Provider Firm’s operators. Client App messaging is end-to-end encrypted; Arbiter holds ciphertext only and cannot read message content.
Voice notes and media — voice notes, photos, and site walkthrough media you or your Provider Firm submit in connection with an Engagement.
3. Information We Collect About You From Other Sources
A core function of the platform is helping your Provider Firm assess and respond to threats to your safety. To do this, your Provider Firm’s operators use tools built into the Provider App to research publicly available and commercially available information about you and, where relevant to your protection, about an Entity of Interest. This research is directed and authorized by your Provider Firm as part of your Engagement, not by Arbiter independently. The categories of sources these tools draw on are:
People and identity data services. Tools that look up publicly and commercially available contact and identity information, such as person, phone, and email lookups, and services that check which online accounts are associated with an email address.
Search engines. General-purpose and AI-assisted search tools used to locate publicly available information and news.
Public records sources. Government and nonprofit sources of public record information, such as corporate filings, court records, federal contractor registrations, campaign contribution records, and nonprofit tax filings.
Web content tools. Tools that retrieve and extract the text of specific, publicly accessible web pages, including archived or historical versions of a page, and domain registration lookup tools.
Social media tools. Tools that retrieve publicly available profile information from social media platforms.
A current, specific list of the third-party sources in each category is maintained in Schedule A to this Policy. We may update Schedule A from time to time to add, remove, or replace a specific source within these categories and for these purposes without separately amending this Policy; we will update this Policy itself, with notice consistent with Section 15, if we add a materially new category of source or use this information for a materially different purpose than described in this Section.
Why FCRA does not govern this information. The Fair Credit Reporting Act (“FCRA”) regulates “consumer reports” — communications bearing on a consumer’s creditworthiness, character, general reputation, or personal characteristics — but only when the report is used or expected to be used for a permissible purpose enumerated in the statute, principally employment, credit, insurance underwriting, or tenant screening. 15 U.S.C. §§ 1681a(d), 1681b. The dossiers, briefs, and other work product your Provider Firm generates through the platform are prepared solely to support your physical protection, not for any FCRA-enumerated purpose, and are never used to make an employment, credit, insurance, or tenancy decision about you or an Entity of Interest. That is the primary reason the FCRA does not govern this information.
Several states impose analogous “mini-FCRA” obligations on consumer reporting agencies that are limited in the same way. Texas, for example, regulates a consumer report only when it is furnished by a consumer reporting agency for an enumerated purpose such as employment, credit, or insurance underwriting. Tex. Bus. & Com. Code §§ 20.02, 20.05. Because the work product described in this Section is not furnished for any such purpose, these state analogs do not apply for the same reason the FCRA does not apply.
An additional safeguard. Independent of that analysis, where a source described in this Section offers a tier of service intended for FCRA-regulated consumer reporting, Arbiter subscribes only to that source’s non-consumer-reporting-agency tier, and that source’s results are contractually restricted from FCRA-regulated use. This applies, for example, to our use of SearchBug.
4. AI-Assisted Processing
Arbiter uses AI models, including Google’s Vertex AI and Gemini, to assist your Provider Firm’s operators — for example, to help analyze site walkthrough media and to draft dossiers, briefs, and after-action reports from the information described in Sections 2 and 3. AI-assisted drafts are reviewed by your Provider Firm’s personnel before being finalized and delivered as an Engagement work product; the fact and timing of that review is recorded in an internal audit record described in the Data Minimization and Retention Policy.
5. Location Information
With your consent, the Client App may collect your live location to support your Engagement. Live location data is held only transiently — it is retained for no more than one hour and no persistent history of your live location is stored. Static location information relevant to your Engagement, such as sites, offices, or scheduled operations, is retained at full precision for the duration of your Engagement, consistent with the Data Minimization and Retention Policy. You may decline to share your live location, though doing so may limit your Provider Firm’s ability to provide certain protective features.
Under California law, precise geolocation is a category of “sensitive personal information,” and California residents have the specific right described in Section 11 to limit our use of it.
6. How We Use Information
We use the information described in this Policy to: operate and provide the Client App and support your Engagement; enable your Provider Firm to assess and respond to threats to your safety; generate the AI-assisted work product described in Section 4; maintain the security, integrity, and availability of the platform; comply with legal obligations described in Section 12; and, in de-identified or aggregated form that does not identify you, improve the platform.
7. How We Share Information
With your Provider Firm. Information you provide and information collected under Section 3 is shared with the Provider Firm operators assigned to your Engagement — this is the core purpose of the platform.
With service providers. We share information with infrastructure and technology vendors that process it on our behalf to operate the platform, subject to contractual confidentiality and security obligations.
With the sources described in Section 3. Queries made to the sources described in Section 3 are subject to those sources’ own privacy practices with respect to information they independently hold; we do not control, and this Policy does not cover, those sources’ own data practices.
For legal and safety reasons. We may disclose information where required by law or legal process, subject to legal review, or where necessary to protect the safety of any person, including you.
We do not sell or share your personal information, as “sell” and “share” are defined under the California Consumer Privacy Act. Our disclosure of your information to your Provider Firm is made at your and your Provider Firm’s direction as part of delivering the Engagement you requested, and our disclosures to service providers are made under contracts that restrict their use of your information to operating the platform on our behalf — neither disclosure constitutes a sale or share of your personal information under that Act.
8. Data Security
We maintain the technical and organizational measures described in the Data Minimization and Retention Policy, together with internal incident-response and legal-preservation procedures, to protect your information. No security measure is perfect, and we cannot guarantee absolute security.
9. Encryption and What We Can and Cannot Access
Depending on your Provider Firm’s configuration, the encryption keys protecting certain Engagement content may be held by Arbiter, by your Provider Firm, or by your organization, under the platform’s bring-your-own-key (“BYOK”) architecture. Where a key is held externally by your Provider Firm or your organization, Arbiter cannot decrypt the associated content, including in response to your own request, because Arbiter does not hold the key. Client App messages are always end-to-end encrypted regardless of key custody tier; Arbiter never holds a decryption key for message content.
10. Data Retention and Deletion
Information collected in connection with your Engagement is retained according to the schedule set out in the Data Minimization and Retention Policy. In general, most Engagement data is retained until your Provider Firm or Arbiter triggers deletion at the end of your Engagement, rather than on a fixed calendar schedule. Certain categories — including live location data, database backups, and the AI audit record described in Section 4 — follow the specific retention rules described in that Policy, including a rule under which the AI audit record is retained for three years and survives deletion of your Engagement, because it documents human review of AI-assisted work product rather than the underlying content itself.
Deletion of Engagement data may be delayed where a litigation hold has been placed.
11. Your Privacy Rights
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA”), gives you the right to:
Know what personal information we have collected about you, including the categories of sources described in Section 3 and the categories of third parties with whom it has been disclosed;
Correct inaccurate personal information;
Delete personal information we have collected about you, subject to exceptions such as completing your Engagement or complying with a legal obligation;
Receive a copy of your personal information in a portable format;
Opt out of the sale or sharing of your personal information — as described in Section 7, we do not sell or share personal information as those terms are defined under the CCPA;
Limit our use of your sensitive personal information — including the precise geolocation described in Section 5 — to what is necessary to provide the protective-security services you have requested, consistent with Cal. Civ. Code § 1798.121; and
Not be discriminated or retaliated against for exercising these rights, consistent with the Client App Terms of Service.
If you are located in another U.S. state with its own comprehensive consumer privacy law, you may have similar rights under that state’s law, and we will honor a valid request consistent with the law that applies to you. If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation, including the rights of access, rectification, erasure, and restriction of processing. To exercise a privacy right, contact us using the information in Section 16; we or your Provider Firm may need to verify your identity before completing a request.
Where Arbiter and your Provider Firm act as joint controllers of certain Engagement information under the GDPR Article 26 Joint Controller Agreement between Arbiter and your Provider Firm, you may exercise your rights against either party, and we will coordinate with your Provider Firm to respond.
12. Law Enforcement and Legal Process
We respond to law enforcement and legal process under procedures that require legal review before any disclosure and, absent a valid non-disclosure order, notice to your Provider Firm of a request concerning your information. Some categories of information — including end-to-end encrypted message content and, where applicable, externally-held encryption keys — cannot be produced by Arbiter regardless of the legal process served, because Arbiter does not have technical access to them.
13. Children and Minors
The Client App is not directed to children under 13, and we do not knowingly collect personal information directly from a child under 13 through the Client App sign-up process. Where an Engagement is intended to protect a minor — for example, a family member of a Client — the minor’s information is provided and consented to by a parent or legal guardian, or by the Provider Firm acting on the family’s behalf, rather than by the minor creating their own account.
14. International Users
The Client App is operated from the United States. If you are located outside the United States, your information will be transferred to, and processed in, the United States. Where information is transferred from the European Economic Area, the United Kingdom, or Switzerland to Arbiter in the United States in connection with a joint-controller relationship with your Provider Firm, that transfer is made consistent with the mechanism described in the GDPR Article 26 Joint Controller Agreement between Arbiter and your Provider Firm.
15. Changes to This Policy
We may update this Policy from time to time. We will post the updated Policy with a new effective date, and where a change is materially adverse to you, we will provide more prominent notice, consistent with the Client App Terms of Service. Schedule A may be updated as described in Section 3 without a change to the body of this Policy.
16. How to Contact Us
If you have questions about this Policy or wish to exercise a privacy right, contact us at legal@arbiterdefense.group or by mail at 1209 Orange Street, Wilmington, Delaware 19801.
Schedule A — Current Third-Party Sources
This Schedule lists the specific third-party sources currently used within each category described in Section 3. Arbiter maintains and may update this Schedule to reflect its current source registry, consistent with Section 3.
| Category | Current Sources |
|---|---|
| People and identity data services | SearchBug (non-CRA tier; not used for FCRA-regulated purposes); Holehe; Hunter.io |
| Search engines | Brave Search; Exa; Perplexity; Tavily |
| Public records sources | SEC EDGAR; SEC-API.io; CourtListener/RECAP; SAM.gov; FEC; ProPublica Nonprofit Explorer |
| Web content tools | Jina Reader; direct web fetch; Wayback Machine/Internet Archive; Wikipedia; WHOIS/RDAP |
| Social media tools | Apify (public-profile data from platforms such as Instagram, TikTok, and LinkedIn) |
| Supporting (enrichment only, not OSINT research) | Google Maps Geocoding (converts an address you or your Provider Firm provide into map coordinates for the dossier) |